It sounds like the execution was skilled, but I haven't heard anything yet that seems technically novel or extraordinary.
Maybe I haven't read the right articles, but it sounds like solarwinds got pwned, and all these big targets loaded the malware onto their own networks...
Again, skillful execution, but it's not like they cracked an encryption algorithm or even did known-but-still-awesome exploits like rowhammer/spectre
I'd call that sophisticated even if just in terms of organizational efforts. Additionally, doing this and not getting caught for 6 months or whatever takes significant discipline from every single person involved. You don't see that level of size, discipline and organization outside a handful of top companies.
1. The actual malicious payload that was installed on the compromised networks was very sophisticated. It was discussed in the HN post when the news first went live, but the payload went to great and pretty ingenious lengths to hide its tracks and prevent detection. I remember a bunch of HN comments along the lines of "Wow, how did the companies ever even find that?!"
2. How SolarWinds was originally breached hasn't been released, and while the "solarwinds123" password is an unrelated issue, it does point to a pretty shocking lack of security culture at SolarWinds.
I'm going to put my chips down on the original breach being quite simple and mundane, but SolarWinds will go (and has already gone) to great lengths to emphasize the sophistication of the attackers to try to deflect blame.
It is non-trivial to write secure deployment scripts/configs and ensure that access keys and credentials can't be leaked to anyone with dev access.